### Impact Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. The fix replaces the hostname comparison with a full-origin comparison (scheme, host, and port), aligning the behavior with the WHATWG Fetch same-origin definition used by browsers. ### Patches Upgrade to >= 18.1.2. ### Workarounds - Set `redirects: 0` (default) and handle redirects manually with a strict origin check. - Use the `beforeRedirect` hook to inspect the redirect target and abort or strip sensitive headers before the follow-on request.
Update @hapi/wreck to 18.1.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects affects @hapi/wreck (npm). Severity is medium. ### Impact Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. The fix replaces the hostname comparison with a full-origin comparison (scheme, host, and port), aligning the behavior with the WHATWG Fetch same-origin definition used by browsers. ### Patches Upgrade to >= 18.1.2. ### Workarounds - Set `redirects: 0` (default) and handle redirects manually with a strict origin check. - Use the `beforeRedirect` hook to inspect the redirect target and abort or strip sensitive headers before the follow-on request.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. The fix replaces the hostname comparison with a full-origin comparison (scheme, host, and port), aligning the behavior with the WHATWG Fetch same-origin definition used by browsers. ### Patches Upgrade to >= 18.1.2. ### Workarounds - Set `redirects: 0` (default) and handle redirects manually with a strict origin check. - Use the `beforeRedirect` hook to inspect the redirect target and abort or strip sensitive headers before the follow-on request.
Update @hapi/wreck to 18.1.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects affects @hapi/wreck (npm). Severity is medium. ### Impact Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. The fix replaces the hostname comparison with a full-origin comparison (scheme, host, and port), aligning the behavior with the WHATWG Fetch same-origin definition used by browsers. ### Patches Upgrade to >= 18.1.2. ### Workarounds - Set `redirects: 0` (default) and handle redirects manually with a strict origin check. - Use the `beforeRedirect` hook to inspect the redirect target and abort or strip sensitive headers before the follow-on request.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| @hapi/wrecknpm | <18.1.2 | 18.1.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| @hapi/wrecknpm | <18.1.2 | 18.1.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard